New Hospital of Toledo: a cybersecurity department without building one
Outsourced cybersecurity departmentContinuous CIS Controls v8 assessmentsENS + GDPR compliance
The challenge
Healthcare is one of the world's most critical sectors: highly sensitive patient data and uninterrupted 24/7 operations where any disruption has direct consequences for patient care. The IT services provider supporting the New Hospital of Toledo — one of Spain's largest hospitals — needed to reach the highest levels of cybersecurity and meet stringent regulatory requirements. Building and maintaining an in-house team with that expertise represented a significant investment in both time and resources.
The solution
We became the organisation's outsourced cybersecurity department, providing CISO as a Service and a dedicated Security Team as a Service, taking full responsibility for its internal cybersecurity programme:
- Audits and security frameworks — regular assessments based on the CIS Critical Security Controls (v8).
- Active defence — comprehensive system and server hardening to minimise the attack surface.
- Governance and compliance — ongoing assurance of healthcare cybersecurity and data protection obligations, including the Spanish National Security Framework (ENS) and GDPR.
The results
- Maximum healthcare resilience — systematic hardening and CIS Controls implementation significantly strengthened hospital systems against threats such as ransomware, supporting uninterrupted care.
- Confidence in compliance — regulatory requirements and audits met with dedicated specialists managing an increasingly complex landscape.
- Greater efficiency and focus — the IT provider optimised costs and freed its internal teams to deliver high-quality technology services to the hospital.